Cross-Site Request Forgery in WWBN AVideo Affects Video Ownership
CVE-2026-58001
6.9MEDIUM
What is CVE-2026-58001?
The WWBN AVideo product has a vulnerability in the videoEditLight.php file that allows attackers to exploit cross-site request forgery (CSRF) weaknesses. This vulnerability permits unauthorized users to insert an img tag within a video description, leading to the potential transfer of video ownership to an attacker-controlled account. The flaw arises from the lack of request authenticity checks in handling GET requests, making it critical for administrators to exercise caution when viewing video pages.
Affected Version(s)
AVideo 0 <= 9c39d8c8b4c1f75540788d6b391740852ceb0732
